Old security vulnerabilities come back to haunt modern industrial and IoT products

September 24, 2020

The importance of security by design has been recently highlighted by a discovery of 19 vulnerabilities in a lightweight TCP/IP library released back in the 1990s, known as Ripple20. Though it was released nearly 30 years ago, this realisation has made organisations across industries more fully aware of cybersecurity flaws they never even knew existed.

Of course, not every vulnerability represents a critical security flaw, but some are very serious and can have effects that allow a hacker to control a device remotely or deny availability. Impacted devices number in the millions, again with varying degrees of criticality. Some, like printers or smart home devices, may not pose immediate safety risks; however, other affected devices include power grid equipment, transportation systems, mobile communication devices, commercial aircraft devices, enterprise systems, and more. With organisations scrambling to ensure that they patch any vulnerabilities, old and new, it’s imperative to ensure that steps are taken that history doesn’t repeat itself.

Security decisions made 20 or 30 years ago for industrial control systems (ICS) or the nascent technology that would develop into IoT were often secondary to functional requirements, such as availability or latency periods. As a consequence, cybersecurity was often treated as an afterthought, with organisations coming up with solutions to secure key devices and systems after they had been created, manufactured and implemented, instead integrating security into the initial design.

This, combined with the traditional divide between OT (operational technology) and IT (information technology) teams, means that organisations are left with vulnerabilities that are can be very difficult to resolve.

Ensuring the security of devices will certainly be key as IoT technology continues to expand and as other industries adopt decentralised networks, spread across devices. By adopting a security tool that can be retrofitted to current and legacy devices, and focusing on integrating security measures during the design process of new devices or networks, organisations can prevent being taken by surprise by old vulnerabilities.

Related Articles

ANGOKA NAMED TOP START-UP AT 2022 ITS EUROPEAN CONGRESS

ANGOKA NAMED TOP START-UP AT 2022 ITS EUROPEAN CONGRESS

At this week’s ITS European Congress in Toulouse, ANGOKA became a multi-award winning start-up, having successfully pitched and won two awards as part of the show’s highly competitive start-up pitching competition.  Hosted by ERTICO, the ITS European Congress is a...

ANGOKA to exhibit at ITS European Congress 2022

ANGOKA to exhibit at ITS European Congress 2022

ANGOKA are preparing to exhibit at this year’s ITS European Congress, joining the global ITS community at Europe’s biggest show for mobility solutions.  Now in its fourteenth year, the ITS European Congress is a landmark event attended by influential figures,...

ANGOKA’s innovation highly commended at Digital DNA Awards

ANGOKA’s innovation highly commended at Digital DNA Awards

ANGOKA's innovation and growth was highly commended at last night's Digital DNA Awards 2022 as we were named runner-up in the Digital Innovation Project of the Year award category.    The Digital Innovation Project of the Year award recognises teams who have delivered...

ANGOKA selected for inaugural Software République startup incubator

ANGOKA selected for inaugural Software République startup incubator

ANGOKA has recently been selected for Software République's startup incubator programme, a project that unites leading companies with innovative startups to accelerate sustainable, secure, and intelligent mobility solutions. As one of five startups selected for the...

ANGOKA Participates in Catalyst’s Generation Innovation Impact Day

ANGOKA Participates in Catalyst’s Generation Innovation Impact Day

As Belfast is the home of our HQ, we are passionate about giving back to the community and thrilled to join other NI tech companies in the Catalyst Generation Innovation Programme, presenting the excitement of the tech sector to the next generation of innovators. Last...

ANGOKA appoints Director of Security Products

ANGOKA appoints Director of Security Products

Belfast-based cybersecurity expert ANGOKA has expanded its team as Robert McCausland joins as Director of Security Products. With extensive experience spanning engineering and technical leadership, Robert has spent the last 16 years designing and delivering Identity...

ANGOKA Wins Self-Driving Industrys Trust Award

ANGOKA Wins Self-Driving Industrys Trust Award

We are delighted to have been awarded in the 'Trust' category at the 'Self-driving Industry' Awards in Margate last week. Hosted by Cars Of The Future, the awards recognise the most compelling innovators in the Connected Autonomous Mobility ecosystem. Our Chief...

Translate »